Описание
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
A flaw was found in udev in systemd. A local user with access to malicious hardware devices can exploit this vulnerability. By providing unsanitized kernel output, the flaw allows for local root execution, leading to privilege escalation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | NetworkManager | Not affected | ||
| Red Hat Enterprise Linux 10 | rpm-ostree | Fix deferred | ||
| Red Hat Enterprise Linux 10 | systemd | Not affected | ||
| Red Hat Enterprise Linux 7 | systemd | Not affected | ||
| Red Hat Enterprise Linux 8 | NetworkManager | Not affected | ||
| Red Hat Enterprise Linux 8 | systemd | Not affected | ||
| Red Hat Enterprise Linux 9 | NetworkManager | Not affected | ||
| Red Hat Enterprise Linux 9 | systemd | Not affected | ||
| Red Hat OpenShift Container Platform 4 | NetworkManager | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
In udev in systemd before 260, local root execution can occur via mali ...
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
EPSS
6.4 Medium
CVSS3